Aller au contenu

Fiche vulnérabilité

CVE-2024-0921 : faille critique dlink dir-816 a2 firmware (CVSS 9.8)

Description

A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/setDeviceSettings of the component Web Interface. The manipulation of the argument statuscheckpppoeuser leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252139.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
26 janv. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • dlink dir-816 a2 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE